Privacy Policy
Last updated July 17, 2026
1. Introduction and Scope
Paraga, Inc. (“Paraga,” “we,” “us,” or “our”) provides software that securely connects the business tools a financial advisory firm already uses (such as its client relationship management system, custodial platforms, financial-planning software, document stores, calendars, and email) to AI assistants and platforms through a permissioned connection, so the firm can read and, when it directs us to, act on its data. This Privacy Policy explains how we handle personal information in connection with our website, our marketing activities, and our services (together, the “Services”).
This Policy covers two different kinds of information with two different roles, described in Section 2. It applies to information about the individuals who administer or use our Services on behalf of a firm (“Account Data”), and it describes, at a high level, how we handle the client and prospect data that a firm connects to us (“Firm Data”). Your firm’s own privacy notices, and its agreement with us, govern the collection and use of Firm Data as between your firm and the individuals it serves.
2. Our Roles: Controller and Processor
Paraga plays two distinct roles depending on the data at issue.
- Controller of Account Data. For information about the firm personnel who sign up for, administer, and use the Services, and for website visitors, Paraga acts as the controller (or “business” under U.S. state privacy laws). We determine how that information is used, and this Policy governs it.
- Processor / subprocessor of Firm Data. For the client and prospect data a firm connects to Paraga through its tools, the firm is the controller (or “business”), and Paraga acts as a processor (or “service provider”), and in many cases a subprocessor of the firm’s other vendors. We access, process, transmit, and act on Firm Data only to provide the Services and only on the documented instructions of the firm. We do not use Firm Data for our own purposes. Our handling of Firm Data is governed by the firm’s agreement with us and our Data Processing Addendum (the “DPA”), which control if they conflict with this Policy as to Firm Data.
3. Information We Collect
We collect the following categories of information:
- Account Data. Names, business email addresses, job titles, firm name, phone numbers, authentication credentials, and role/permission settings for the individuals who register for or use the Services.
- Connected Firm Data. When a firm connects a tool, we access the data the firm authorizes us to access. Depending on the tools connected, this may include client and prospect contact details, account and portfolio information, financial-planning inputs, documents, notes, meeting and calendar entries, and email content. This data may include nonpublic personal information and other sensitive financial information belonging to the firm’s clients.
- Usage and Technical Data. Log data, device and browser information, IP address, connection and configuration metadata, feature usage, audit records of actions taken through the Services, and diagnostic and error information.
4. How We Use Information
We use Account Data to provide, maintain, secure, and improve the Services; to authenticate users and administer permissions; to communicate with you about the Services, including service and security notices; to provide support; to send marketing communications you can opt out of; to detect, prevent, and respond to fraud, abuse, and security incidents; and to comply with law and enforce our agreements.
We use Firm Data only to provide the Services to your firm and only per your firm’s instructions, including reading data your firm connects, presenting it to the AI assistant your firm has chosen, and carrying out the read or write actions your firm instructs. We use Usage and Technical Data to operate, secure, troubleshoot, and improve the Services. We do not sell personal information, and we do not use Firm Data to train, fine-tune, or improve any generative AI model.
5. Legal Bases for Processing
Where applicable data protection law requires a legal basis, we rely on the following for our processing of Account Data: performance of our contract with you or your firm; our legitimate interests in operating, securing, and improving the Services and in marketing to business contacts (balanced against your rights); your consent where required; and compliance with legal obligations. For Firm Data, our processing is carried out on behalf of, and under the instructions and legal bases established by, your firm as controller.
6. AI Providers, No Training, and Zero Data Retention
The Services connect your firm’s data to third-party AI platforms (such as Claude, ChatGPT, Gemini, and Copilot) or to a custom interface your firm selects. When your firm instructs the Services to send data to one of these AI providers, that provider processes the data to generate the requested output.
We contract with AI providers as a customer and configure these integrations to protect Firm Data. Specifically: we do not permit AI providers to use Firm Data to train or improve their models; and we enable zero-data-retention settings where the provider makes them available, so that prompt and output data is not retained by the provider beyond what is necessary to return a result. Where a provider does not offer a zero-retention option for a given feature, we limit use to providers and configurations consistent with our commitments to your firm. We maintain a current list of AI providers and other subprocessors, which we provide on request.
Google User Data and Limited Use
When you authorize a Google connection, Paraga accesses your Google data (such as your Gmail messages, threads, labels, and related metadata, and your Google Calendar list and event details) only through the permissions you grant, and only to provide the Paraga features you use: identifying advisor-client communications and meetings, presenting them in the appropriate client record and search results, keeping those records current, and answering or summarizing questions an authorized user asks about the firm’s client book. What Paraga can access, and whether it can act on your behalf (for example, drafting or updating messages or calendar events), is limited to the permissions you approve when you connect, and you can review or revoke those permissions at any time in your Google Account.
Paraga’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized artificial-intelligence or machine-learning models, we do not sell Google user data, and we do not use it for advertising.
7. How We Share Information
We share information only as follows:
- Subprocessors. We use vetted third-party providers for hosting, infrastructure, AI processing, security, analytics, and support. Each is bound by contract to protect the information consistent with this Policy and our DPA. Our current subprocessors are identified in a subprocessor list we provide on request.
- At your direction. We share and act on Firm Data with the tools and AI platforms your firm connects and instructs us to use.
- Legal and safety. We may disclose information to comply with law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Paraga, our customers, or others.
- Business transfers. If Paraga is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy and the confidentiality and processing commitments in place.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
8. Financial Data, GLBA, and Regulation S-P
Firm Data frequently includes “nonpublic personal information” as defined under the Gramm-Leach-Bliley Act (GLBA) and information subject to the SEC’s Regulation S-P. We handle such information as a service provider to the advisory firm. We maintain administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of this information, and we support our customers’ obligations under the GLBA Safeguards Rule and Regulation S-P, including through written safeguards commitments, service-provider oversight cooperation, and incident-response and breach-notification support. We are available to enter into a DPA that includes Regulation S-P and GLBA-aligned terms as part of a firm’s vendor diligence.
9. Data Location and Security
Firm Data and Account Data are stored and processed in the United States. We protect information using a defense-in-depth security program that includes: encryption of data in transit using TLS 1.2 or higher; encryption of data at rest; role-based access controls and least-privilege access; authentication and secrets management; network and infrastructure hardening; logging and monitoring; and regular review of our controls. Credentials and connection tokens used to access connected tools are stored using strong encryption.
No system is perfectly secure. If we become aware of a security incident affecting personal information, we will notify affected customers without undue delay and will cooperate with them to meet their notification obligations, including the customer-notification timeframe under Regulation S-P.
10. Data Retention and Deletion
We retain Account Data for as long as your account is active and as needed to provide the Services, and thereafter as required to comply with legal obligations, resolve disputes, and enforce our agreements. We retain Firm Data only as directed by your firm and as described in our agreement and DPA; because we configure AI providers for zero retention where available, prompt and output content is not persisted by those providers beyond returning a result. On termination, or on your firm’s instruction, we delete or return Firm Data in accordance with the DPA, subject to limited retention required by law or contained in routine backups that are cycled out on a defined schedule.
11. Cookies and Analytics
Our website uses cookies and similar technologies for essential functionality, to remember preferences, and to understand and improve how the site is used. We use a limited set of privacy-respecting analytics tools. You can control cookies through your browser settings; disabling some cookies may affect site functionality. We honor recognized opt-out preference signals (such as Global Privacy Control) where legally required.
12. Your Privacy Rights
Depending on where you live, you may have rights over your personal information, including the rights to access the personal information we hold about you, to delete it, to correct inaccuracies, to obtain a portable copy, to opt out of any sale or sharing of personal information (note: we do not sell or share personal information for cross-context behavioral advertising), and to be free from discrimination for exercising your rights. Residents of California under the CCPA/CPRA and residents of other U.S. states with comprehensive privacy laws may exercise these rights.
To exercise a right regarding Account Data, contact us at support@paraga.ai. We will verify your request and respond within the timeframe required by law. You may use an authorized agent where permitted. If your request concerns a firm’s client data (Firm Data) that we process on a firm’s behalf, we will refer your request to that firm as the controller, or act on the firm’s instructions, and you should contact the firm directly.
13. Automated Processing and Human Oversight
The Services use AI to read, summarize, and prepare actions on data. The Services are designed to operate under the direction and oversight of the firm’s personnel: actions that write to a firm’s systems or take effect on a client’s data occur based on the firm’s configuration and instructions, with human review available in the workflow. We do not use the Services to make legally significant decisions about individuals without human involvement. Paraga is not a registered investment adviser, broker-dealer, or custodian, and does not provide investment, legal, tax, or other professional advice.
14. Children’s Privacy
The Services are intended solely for business use by financial advisory firms and their authorized personnel, who must be at least 18 years old. The Services are not directed to children, and we do not knowingly collect personal information directly from anyone under 18. Firm Data provided by a firm about its own clients is the responsibility of the firm as controller.
15. International Users
The Services are offered from and operated in the United States and are intended for customers located in the United States. Information is stored and processed in the United States. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law, and you understand your information will be processed in the United States.
16. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice as appropriate. Your continued use of the Services after an update means you accept the revised Policy.
17. Contact Us
Questions, requests, or complaints about this Policy or our privacy practices can be sent to support@paraga.ai. Paraga, Inc. is a Delaware corporation.